Key facts
- Hackers are utilizing BNB Smart Chain contracts to store and distribute malware instructions.
- Victims are prompted by fake CAPTCHAs to paste malicious commands into Windows tools like Run, Terminal, or PowerShell.
- The EtherHiding technique embeds malicious instructions within blockchain smart contracts, making them resistant to conventional takedowns.
- Successful exploitation can lead to credential theft, persistent network access, and potential ransomware attacks.
- Microsoft has observed thousands of enterprise and consumer devices targeted daily by these campaigns.
Cybercriminals are exploiting BNB Smart Chain contracts to host malware instructions, which are then delivered to unsuspecting users through fake CAPTCHA prompts on compromised websites. This method, identified by Microsoft Threat Intelligence as EtherHiding, embeds malicious commands within blockchain smart contracts, making them difficult to remove and evade traditional security measures.
